Intelligence View
⚡ tsecurity.de Intelligence
Cisco Sinkholes GozNym Banking Trojan Botnet
The Cisco Talos team announced today that they've successfully managed to sinkhole one of GozNym's botnets and are in the process of doing the same to three others. Researchers say they were able to divert traffic from the GozNym botnet…
Reagiere als Erste:r — dein Feedback zählt!
The Cisco Talos team announced today that they've successfully managed to sinkhole one of GozNym's botnets and are in the process of doing the same to three others.
Researchers say they were able to divert traffic from the GozNym botnet after they managed to crack the domain name generation algorithm (DGA) used by the banking trojan to communicate with its ever-changing C&C master servers.
All banking trojans today, and other types of top-shelf malware, use DGAs to allow infected hosts to communicate with C&C servers that change on a daily basis.
Cracking the DGA is the quickest way to sinkhole malware operations
A DGA uses various input data to generate a random domain name to which the infected host connects. Because crooks know how the algorithm behaves they know what domain name is generated every day, and will host servers on those domains in advance, so to manage the botnet on that specific day.
If researchers manage to crack the DGA, they...
Researchers say they were able to divert traffic from the GozNym botnet after they managed to crack the domain name generation algorithm (DGA) used by the banking trojan to communicate with its ever-changing C&C master servers.
All banking trojans today, and other types of top-shelf malware, use DGAs to allow infected hosts to communicate with C&C servers that change on a daily basis.
Cracking the DGA is the quickest way to sinkhole malware operations
A DGA uses various input data to generate a random domain name to which the infected host connects. Because crooks know how the algorithm behaves they know what domain name is generated every day, and will host servers on those domains in advance, so to manage the botnet on that specific day.
If researchers manage to crack the DGA, they...
2. Cyber Threat Intelligence & Forensik
CTI Threat Relationship Graph4 Knoten / 3 Relationen